GELİŞMİŞ KALICI TEHDİTLERİN İNCELENEREK SİBER GÜVENLİK TEHDİTLERİNİ TESPİT EDEN ARACIN GELİŞTİRİLMESİ
| dc.contributor.advisor | ERTAM, FATİH | |
| dc.contributor.author | CIRIK, MEHMET KADİR | |
| dc.date.accessioned | 2026-08-12T10:09:48Z | |
| dc.date.issued | 2026 | |
| dc.department | FÜ, Fen Bilimleri Enstitüsü, Adli Bilişim Anabilim Dalı | |
| dc.description.abstract | Gelişmiş kalıcı tehditler (Advanced Persistent Threats - APT), kritik bilgi sitemlerini hedef alarak uzun süre tespit edilmeden faaliyet gösterebilen sofistike saldırılar arasında yer almaktadır. Bu çalışma, APT'lerin davranışsal analizine dayalı olarak, saldırı yüzeylerini ve tekniklerini incelemekte ve bu incelemelerden elde edilen bulgular ışığında Python tabanlı bir tehdit tespit sistemi geliştirmektedir. Araştırma kapsamında, APTSimulator adlı açık kaynaklı bir araç temel alınmıştır. APTSimulator, Windows ortamında APT saldırılarını simüle etmekte ve saldırganların sistem üzerinde gerçekleştirebileceği çeşitli aktiviteleri taklit ederek güvenlik izleme araçlarının ve olay müdahale ekiplerinin tespit yeteneklerini değerlendirmeye olanak sağlamaktadır. Araç, saldırı vektörlerinin modellenmesi, sistem üzerindeki etkilerinin gözlemlenmesi ve simüle edilen saldırılardan elde edilen veri çıktılarının analiz edilmesi gibi kritik işlevler sunmaktadır. Simülasyon sürecinde, kimlik bilgisi hırsızlığı, keşif faaliyetleri, komuta kontrol bağlantıları (C2), zararlı yazılım teknikleri ve yetki yükseltme girişimleri gibi farklı saldırı senaryoları ele alınmıştır. Bu senaryolardan elde edilen veriler, tehdit tespit sisteminin algoritmalarını güçlendirmek ve doğrulamak amacıyla kullanılmıştır. Sistem, saldırgan aktivitelerini davranış temelli analiz yöntemleriyle inceleyerek, hızlı ve etkili bir şekilde tespit etmektedir. Bu tez çalışmasında elde edilen bulgular, APT saldırılarının dinamiklerinin daha derinlemesine anlaşılmasını sağlamakta ve bu tür tehditlerin önlenmesi veya erken tespit edilmesi için yeni bir yaklaşım sunmaktadır. Özellikle olay müdahale ekipleri ve güvenlik ürünlerinin etkinliğini artırmayı hedefleyen bu sistem, saldırı yüzeylerinin daha iyi kavranmasına ve müdahale süreçlerinin hızlanmasına katkı sağlamaktadır. Elde edilen sonuçlar, hem akademik literatüre katkı sunmakta hem de pratik uygulamalara yönelik bir çözüm geliştirilmesini mümkün kılmaktadır. Bu bağlamda, siber güvenlik alanında APT tehditlerinin tespitine yönelik önemli bir ilerleme kaydedilmiştir. | |
| dc.description.abstract | Advanced persistent threats (APTs) are sophisticated attacks that target critical information systems and can operate undetected for extended periods. This study examines the attack surfaces and techniques of APTs through behavioral analysis and develops a Python-based threat detection system based on the findings. The research leverages an open-source tool called APTSimulator. APTSimulator simulates APT attacks in Windows environments, mimicking various activities attackers might perform on a system. This enables security monitoring tools and incident response teams to evaluate their detection capabilities. The tool offers critical functionalities such as modeling attack vectors,observing their effects on the system, and analyzing data outputs from simulated attacks. During the simulation process, scenarios such as credential theft, reconnaissance activities, command and control (C2) connections, malware techniques, and privilege escalation attempts are addressed. Data obtained from these scenarios strengthens and validates the threat detection system's algorithms. The system employs behavior-based analysis methods to detect malicious activities quickly and effectively. The findings of this thesis provide a deeper understanding of the dynamics of APT attacks and offer a new approach to preventing or detecting such threats early. The system, designed to enhance the efficiency of incident response teams and security products, contributes to better comprehension of attack surfaces and accelerates response processes. The results offer both academic contributions and practical solutions, representing significant progress in detecting APT threats in the field of cybersecurity. | |
| dc.identifier.citation | CIRIK, M. (2026). Gelişmiş kalıcı tehditlerin incelenerek siber güvenlik tehditlerini tespit eden aracın geliştirilmesi (Tez No. 1000732) [Yüksek lisans tezi, Fırat Üniversitesi]. | |
| dc.identifier.uri | https://tez.yok.gov.tr/UlusalTezMerkezi/TezGoster?key=5T1_CZ5-UGb9QCmoURec4K56ZQAWFQBpnh4WsK0kBNh4sUXB1xnWvTxl5w7r8d6g | |
| dc.identifier.uri | https://hdl.handle.net/11508/22509 | |
| dc.identifier.yoktezid | 1000732 | |
| dc.language.iso | tr | |
| dc.publisher | Fırat Üniveristesi | |
| dc.relation.publicationcategory | Tez | |
| dc.rights | info:eu-repo/semantics/openAccess | |
| dc.snmz | KA_TEZ_20260511 | |
| dc.subject | Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol | |
| dc.title | GELİŞMİŞ KALICI TEHDİTLERİN İNCELENEREK SİBER GÜVENLİK TEHDİTLERİNİ TESPİT EDEN ARACIN GELİŞTİRİLMESİ | |
| dc.title.alternative | Development of a thread detection tool through the analysis of advanced persistent threats in cybersecurity | |
| dc.type | Master Thesis |







